Linux.MulDrop.14 is a Linux worm that searches for Raspberry Pi network systems whose default root password has not been changed, and after infiltrating them and obtaining ZMap and sshpass, it begins mining an unspecified cryptocurrency. In this way, the infected Raspberry Pi will become a source of revenue for the creator of this Linux worm.

Experts say that initial infection will occur when Raspberry Pi operators keep their devices’ SSH ports and external connections open.

After a Raspberry Pi-based device is affected by Linux Maldrop 14, the malware changes the default password for the “pi” user account to the following:

\$6\$U1Nu9qCp\$FhPuo8s5PsQlH6lwUdTwFcAUPNzmr0pWCdNJj.p6l4Mzi8S867YLmc7BspmEH95POvxPQ3PzP029yT1L3yi6K1

 

Read more